论文部分内容阅读
(2)检测原理 1)基于行为的检测 基于行为的检测因为与系统相对无关,通用性较强。甚至有可能检测出以前未出现过的攻击方法,不象基于知识的检测那样受已知脆弱性的限制。但因为不可能对整个系统内的所有用户行为进行全面的描述,况且每个用户的行为是经常改变的,所以它的主要缺陷在于误检率很高。尤其在用户数目众多,或工作目的经常改变的环境中。其次由于统计简表要不断更新,入侵者如果知道某系统在异常检测器的监视之下,他们能慢慢地训练检测系统,以至于最初认为是异常的行为,经一段时间训练后也认为是正常的了。基于行为的具体检测方法大致有以下几种:
(2) Detection principle 1) Behavior-based detection Behavior-based detection is relatively generic and relatively versatile. It is even possible to detect attacks that have not previously taken place, unlike the knowledge-based detection that is limited by the known vulnerabilities. However, because it is impossible to describe all user behaviors in the whole system in a comprehensive way, and the behavior of each user changes frequently, its main defect is the high false detection rate. Especially in an environment where the number of users is large or the purpose of work is constantly changing. Second, as the statistical profile is constantly updated, if an intruder knows that a system is under the surveillance of an anomaly detector, they can slowly train the detection system so that behavior initially thought to be abnormal is considered to be after a period of training Normal Specific testing methods based on the behavior are generally the following: